
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34269 is an Improper Access Control vulnerability in the Portal component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.61 and 8.62. It was disclosed on April 21, 2026, as part of Oracle's April 2026 Critical Patch Update. The vulnerability allows an unauthenticated remote attacker to compromise the system via HTTP, though successful exploitation requires human interaction (user interaction required). It carries a CVSS v3.1 base score of 6.1 (Medium) (Oracle Advisory, Github Advisory). The vulnerability was reported to Oracle by John Kounelis (Oracle Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control), residing in the Portal component of PeopleSoft Enterprise PeopleTools. An unauthenticated attacker with network access via HTTP can exploit this flaw by crafting a malicious HTTP request that, when interacted with by a victim user, bypasses security controls in the Portal component. The attack has low complexity and requires no privileges, but does require user interaction to trigger. Notably, the scope is marked as "Changed," meaning a successful attack can impact resources beyond the vulnerable PeopleTools component itself, potentially affecting additional integrated Oracle products (Oracle Advisory, Github Advisory).
Successful exploitation results in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized update, insert, or delete access to some accessible data — impacting both confidentiality and integrity, with no availability impact. The changed scope means the attack can extend beyond PeopleTools itself to potentially affect additional connected Oracle products or systems. This could expose sensitive enterprise HR, financial, or operational data managed through PeopleSoft (Oracle Advisory).
Oracle has released patches for this vulnerability as part of the April 2026 Critical Patch Update, covering PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Organizations should apply the Oracle Critical Patch Update patches immediately (Oracle Advisory). As interim mitigations, Oracle recommends blocking network protocols required by the attack at the network level, restricting access to the PeopleTools Portal component, and educating users about the risks of interacting with untrusted requests. Additional controls such as placing additional authentication or authorization layers in front of the Portal component and monitoring access logs for suspicious activity targeting the Portal are also advised.
Oracle disclosed this vulnerability as part of its quarterly Critical Patch Update on April 21, 2026, which contained 481 new security patches across product families. No notable independent researcher commentary, social media discussion, or significant media coverage specific to CVE-2026-34269 has been identified beyond standard CVE tracking and advisory aggregation sites (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."